# HILFE - Fehler - The provided X-CSRF-Token is invalid

**URL:** <https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618>\
**Category:** Programmierung\
**Created:** [18. Oktober 2016 um 09:31 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618 "2016-10-18T09:31:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![saegeketten](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@saegeketten](https://forum.shopware.com/u/saegeketten)\
**Post date:** [18. Oktober 2016 um 09:31 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/1 "2016-10-18T09:31:03Z")

</div>

Hallo liebe Shopware Gemeinde,

Diesen Fehler erhalte ich 20x am Tag. Mein Shopware shop 5.2.8 und alle Module laufen aber&nbsp;einwandfrei. &nbsp;[www.schwarze-Handtaschen.de](http://www.schwarze-Handtaschen.de)&nbsp;

Habt&nbsp;ihr eine Idee, woran das liegen könnte?

lg Carmen

* * *

**ERROR Message:**

```
 exception 'Shopware\Components\CSRFTokenValidationException' with message 'The provided X-CSRF-Token is invalid. Please go back, reload the page and try again.' in /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Shopware/Components/CSRFTokenValidator.php:161

 Stack trace:

 #0 [internal function]: Shopware\Components\CSRFTokenValidator-\>checkFrontendTokenValidation(Object(Enlight\_Controller\_ActionEventArgs))

 #1 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Library/Enlight/Event/Handler/Default.php(91): call\_user\_func(Array, Object(Enlight\_Controller\_ActionEventArgs))

 #2 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Library/Enlight/Event/EventManager.php(214): Enlight\_Event\_Handler\_Default-\>execute(Object(Enlight\_Controller\_ActionEventArgs))

 #3 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Library/Enlight/Controller/Action.php(143): Enlight\_Event\_EventManager-\>notify('Enlight\_Control...', Object(Enlight\_Controller\_ActionEventArgs))

 #4 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Library/Enlight/Controller/Dispatcher/Default.php(523): Enlight\_Controller\_Action-\>dispatch('indexAction')

 #5 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Library/Enlight/Controller/Front.php(223): Enlight\_Controller\_Dispatcher\_Default-\>dispatch(Object(Enlight\_Controller\_Request\_RequestHttp), Object(Enlight\_Controller\_Response\_ResponseHttp))

 #6 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Shopware/Kernel.php(177): Enlight\_Controller\_Front-\>dispatch()

 #7 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/vendor/symfony/http-kernel/HttpCache/HttpCache.php(487): Shopware\Kernel-\>handle(Object(Symfony\Component\HttpFoundation\Request), 1, true)

 #8 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Shopware/Components/HttpCache/AppCache.php(255): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>forward(Object(Symfony\Component\HttpFoundation\Request), true, NULL)

 #9 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/vendor/symfony/http-kernel/HttpCache/HttpCache.php(258): Shopware\Components\HttpCache\AppCache-\>forward(Object(Symfony\Component\HttpFoundation\Request), true)

 #10 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/vendor/symfony/http-kernel/HttpCache/HttpCache.php(275): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>pass(Object(Symfony\Component\HttpFoundation\Request), true)

 #11 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Shopware/Components/HttpCache/AppCache.php(133): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>invalidate(Object(Symfony\Component\HttpFoundation\Request), true)

 #12 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/vendor/symfony/http-kernel/HttpCache/HttpCache.php(206): Shopware\Components\HttpCache\AppCache-\>invalidate(Object(Symfony\Component\HttpFoundation\Request), true)

 #13 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/engine/Shopware/Components/HttpCache/AppCache.php(114): Symfony\Component\HttpKernel\HttpCache\HttpCache-\>handle(Object(Symfony\Component\HttpFoundation\Request), 1, true)

 #14 /var/www/vhosts/schwarze-handtaschen.de/shopware.schwarze-handtaschen.de/72015/shopware.php(113): Shopware\Components\HttpCache\AppCache-\>handle(Object(Symfony\Component\HttpFoundation\Request))

 #15 {main}

```

**Time:**

```
 2016-10-18T09:49:37.834230+0200

```

**Channel:**

```
 core

```

**request:**

```
 {

 &nbsp;&nbsp;&nbsp; "uri": "/newsletter",

 &nbsp;&nbsp;&nbsp; "method": "POST",

 &nbsp;&nbsp;&nbsp; "query": {

 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "module": "frontend",

 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "controller": "newsletter",

 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "action": "index"

 &nbsp;&nbsp;&nbsp; },

 &nbsp;&nbsp;&nbsp; "post": {

 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "subscribeToNewsletter": "1",

 &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; "newsletter": ""

 &nbsp;&nbsp;&nbsp; }

 }

```

**session:**

```
 No session data available

```

**shopId:**

```
 1

```

**shopName:**

```
 DE

```

&nbsp;

---

<div class="post-metadata">

**Author:** ![SVH\_Handels\_GmbH](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@SVH\_Handels\_GmbH](https://forum.shopware.com/u/SVH_Handels_GmbH)\
**Post date:** [18. Oktober 2016 um 09:43 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/2 "2016-10-18T09:43:30Z")

</div>

Hallo Carmen,

&nbsp;

mal kurz die Suche hier im Forum benutzt und schon kommt das:

[https://forum.shopware.com/discussion/41201/checkout-invalid-token-exception/p1](https://forum.shopware.com/discussion/41201/checkout-invalid-token-exception/p1)

Schau mal, ob dir das weiter hilft. Ansonsten gibt es noch ne Menge anderer Beiträge zu diesem Thema.

---

<div class="post-metadata">

**Author:** ![saegeketten](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@saegeketten](https://forum.shopware.com/u/saegeketten)\
**Post date:** [18. Oktober 2016 um 09:46 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/3 "2016-10-18T09:46:55Z")

</div>

Hallo,

nett von dir, danke, dann schau ich mir das mal an.

lg Carmen

---

<div class="post-metadata">

**Author:** ![saegeketten](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@saegeketten](https://forum.shopware.com/u/saegeketten)\
**Post date:** [18. Oktober 2016 um 09:50 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/4 "2016-10-18T09:50:06Z")

</div>

hallo,

gelesen habe ich es, aber ich weiß nicht, was ich zun soll?

Hat jemand eine Anleitung, was ich am Shop GENAU nun machen sollte?

ög Carmen

---

<div class="post-metadata">

**Author:** ![SVH\_Handels\_GmbH](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@SVH\_Handels\_GmbH](https://forum.shopware.com/u/SVH_Handels_GmbH)\
**Post date:** [18. Oktober 2016 um 10:11 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/5 "2016-10-18T10:11:13Z")

</div>

Wie im dem Thread beschrieben, entweder CSRF abschalten oder Session Laufzeit erhöhen:

&nbsp;

> [@NextMike schrieb:](https://forum.shopware.com/profile/19433/NextMike "NextMike")
> 
> Evtl. ist die ganze CSRF Geschichte nicht ausgereift. Hier steht wie sie abgeschaltet werden kann:
> 
> [https://developers.shopware.com/developers-guide/csrf-protection/](https://developers.shopware.com/developers-guide/csrf-protection/?_ga=1.228385373.154808025.1475241903)

&nbsp;

> [@Moritz Naczenski schrieb:](https://forum.shopware.com/profile/14574/Moritz%20Naczenski "Moritz%20Naczenski")
> 
> Der CSRF-Cookie bekommt die Laufzeit der Session (auf vielen Servern 24 Minuten). Wenn du diese Zeit wartest und dann ohne eine Seite aufzurufen direkt einen POST-Request ausführst, dann ist die Meldung völlig korrekt, denn du hast den Cookie ja auch noch garnicht. Der Sinn des Cookies ist ja, dass man ohne diesen keine POST-Requests ausführen kann.
> 
> Sehe da so erstmal keinen Fehler. Du kannst ggf. deine Session lifetime erhöhen um dem zu entgehen.

&nbsp;

---

<div class="post-metadata">

**Author:** ![saegeketten](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@saegeketten](https://forum.shopware.com/u/saegeketten)\
**Post date:** [18. Oktober 2016 um 10:15 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/6 "2016-10-18T10:15:34Z")

</div>

mmh, danke, aber das ist nicht verständlich für mich… ![Frown](https://europe1.discourse-cdn.com/flex013/uploads/shopware/original/1X/569ff272a6dd35730487f053b5b3cd1f98b23eea.png "Frown")

- Wohin gehe ich im Shop Backend?
- Wo klicke ich hin?
- Was gebe ich wo ein?
- Anleitung In Deutsch möglich?

ich bin keine Programmierin

lg Carmen

---

<div class="post-metadata">

**Author:** ![SVH\_Handels\_GmbH](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@SVH\_Handels\_GmbH](https://forum.shopware.com/u/SVH_Handels_GmbH)\
**Post date:** [18. Oktober 2016 um 10:55 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/7 "2016-10-18T10:55:16Z")

</div>

Dies kann man nicht im Backend einstellen. Das muss in der config.php abgeschaltet werden.

Bitte einmal die Suche im Forum nutzen! Suche nach “The provided X-CSRF-Token is invalid”

Dort gibt es viele Beiträge und Lösungsvorschläge. Das Abschalten des CSRF Schutzes führt allerdings nur zum “unterdrücken” der Fehlermeldung. Dies behebt nicht die Ursache.

Vermutlich ist ein Plugin daran Schuld.Kürzlich ein SW Update durchgeführt? Eventuell Plugins installiert, welche mit der SW Version nicht kompatibel sind? etc pp.

---

<div class="post-metadata">

**Author:** ![saegeketten](https://avatars.discourse-cdn.com/v4/letter/s/c6cbf5/32.png) [@saegeketten](https://forum.shopware.com/u/saegeketten)\
**Post date:** [18. Oktober 2016 um 11:16 UTC](https://forum.shopware.com/t/hilfe-fehler-the-provided-x-csrf-token-is-invalid/40618/8 "2016-10-18T11:16:06Z")

</div>

danke &nbsp; ![Wink](https://europe1.discourse-cdn.com/flex013/uploads/shopware/original/1X/b3785da0cbf2c8566cb535dcf55b2730b5224899.png "Wink")

lg Carmen
